Jurisdiction Guides / Asia-Pacific
New Zealand Privacy & Data Protection Laws
Every regime below can apply to a business handling New Zealand residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Section 4 is unusually direct about extraterritoriality: the Act applies to an overseas agency 'carrying on business in New Zealand' whether or not it has a place of business there, whether or not it makes a monetary profit, and regardless of where the personal information is held — an accessible website plus real commercial engagement with New Zealanders is the practical threshold, so the offering-goods limb is modeled as a trigger here. New Zealand holds a European Commission adequacy decision. Notifiable privacy breaches must be reported to the Office of the Privacy Commissioner and affected individuals where serious harm is likely. The Privacy Amendment Act 2025 added information privacy principle 3A, requiring agencies that collect personal information indirectly (from a source other than the individual) to notify the individual — the significant new duty for data brokers, enrichment vendors, and anyone building profiles from third-party sources; confirm its commencement date against the OPC before assuming it is or is not yet operative.
Cross-Border Data Transfer · 1
IPP 12 was new in the 2020 Act and it is a belief-based test rather than a filing or an approval: an agency may disclose personal information to a foreign person or entity only if it believes on reasonable grounds that at least one condition is met — the recipient carries on business in New Zealand and is therefore itself subject to the Act; or is subject to privacy laws that overall provide comparable safeguards; or is required, for example by agreement between the agencies, to protect the information in a way that overall provides comparable safeguards; or is subject to the laws of a country, or a participant in a binding scheme, that regulations have PRESCRIBED as providing comparable safeguards. The Privacy Commissioner publishes model clauses for the agreement route, which is what most businesses use. Marked 'check' on one point worth confirming before relying on it: the prescribed-country route depends on regulations actually being made, and the Ministry of Justice was still consulting on which countries to prescribe — do not assume a destination is prescribed without checking. Note also that IPP 12 governs DISCLOSURE, and sending information to an agent that holds it solely on your behalf is treated differently under the Act.
Data Security & Breach Notification · 1
An agency must notify the Privacy Commissioner as soon as practicable after becoming aware of a notifiable privacy breach — one that has caused or is likely to cause serious harm to an affected individual — and must also notify the affected individuals. There is no numeric deadline. What gives the duty teeth is s. 118: failing to notify the Commissioner without reasonable excuse is a criminal offence carrying a fine of up to NZD 10,000, which makes New Zealand one of the few regimes in this dataset where non-notification is itself an offence rather than a civil contravention. 'Agency' is defined broadly and includes overseas agencies carrying on business in New Zealand, whether or not they have a place of business there.
Other Asia-Pacific jurisdictions